ASD Alerts: Cyber Attacks Targeting Australian Adobe Commerce and Magento Stores
We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!
Quick Overview
- Critical flaw CVE-2026-75650 impacts Adobe Commerce and Magento Open Source, assessed at 10.0 on the CVSS scale.
- Exploitation commenced on September 4, giving attackers a three-day period before Adobe’s patch was released.
- The Australian Cyber Security Centre (ACSC) indicates numerous potentially affected instances in Australia.
- Merchants are urged to implement patches right away and keep an eye out for suspicious actions.
ASD Alert: Australian Adobe Commerce and Magento Stores at Risk
The Australian Signals Directorate (ASD) has issued a critical alert concerning a major vulnerability in Adobe Commerce and Magento Open Source systems. This vulnerability, designated CVE-2026-75650, has been evaluated as 10.0 on the CVSS scale, signifying a critical risk level. It permits unauthorised remote code execution, presenting a serious threat to online retailers utilizing these platforms in Australia.
Grasping the Vulnerability
This vulnerability is produced by the inadequate neutralisation of special characters within a template engine, which can permit unauthenticated remote code execution. The ASD’s Australian Cyber Security Centre (ACSC) states that exploitation hinges on exposing the /graphql endpoint.
Attack Strategy
The method of attack is intricate, evading clear injection points by altering “styles” properties in a GraphQL request. This tactic allows PHP code to bypass input validation and integrate into a file created during regular processes, such as a payment error report.
Effect on Australian Enterprises
The ACSC has detected a significant number of potentially vulnerable instances scattered across Australia. Although precise counts of affected stores are yet to be established, the threat to Australian enterprises is considerable, demanding swift action.
Detection and Reaction
This vulnerability was identified by the Dutch ecommerce security firm Sansec, who dubbed it StyleSmuggler. Exploitation began on September 4, with the first confirmed breach occurring at 22:20 UTC. Sansec published their findings on September 5, before Adobe provided a CVE identifier or advisory.
Adobe’s Action
Adobe reacted with a hotfix, but attackers had a vital three-day period to exploit the flaw. ASD recommends impacted organizations to assess their networks, apply essential patches, and monitor for any suspicious behavior. Merchants are also encouraged to rotate the Magento encryption key and credentials.
Previous Vulnerabilities
In recent times, Adobe Commerce and Magento platforms have encountered multiple severe vulnerabilities. Past issues consist of CosmicSting (CVE-2024-34102) and SessionReaper (CVE-2025-54236), both leading to notable breaches and exploitations.
Conclusion
The recent vulnerability in Adobe Commerce and Magento platforms poses a critical threat to online businesses in Australia. Immediate measures are necessary to alleviate risks, with organizations advised to implement patches and observe for unusual conduct. The ongoing challenges emphasize the necessity for strong cybersecurity practices in the ecommerce industry.
Reader questions
Frequently asked questions
Fast answers to the questions readers ask most about ASD Alerts: Cyber Attacks Targeting Australian Adobe Commerce and Magento Stores.
What is CVE-2026-75650?
CVE-2026-75650 is a significant vulnerability in Adobe Commerce and Magento platforms that allows unauthenticated remote code execution.
How can businesses safeguard themselves?
Businesses should apply the latest updates from Adobe, monitor for unusual activities, and adhere to ASD’s mitigation recommendations.
Are there indicators of compromise to monitor?
Signs of compromise may include unexpected alterations in the system or atypical network traffic. Continuous monitoring and regular audits are recommended.
How can third-party managed services assist?
Managed service providers can ensure that software is updated and secure, providing additional monitoring and response capabilities.
What historical vulnerabilities have impacted these platforms?
Previous vulnerabilities include CosmicSting and SessionReaper, both of which resulted in serious exploitations and breaches.
What steps should merchants take if they believe their store is compromised?
Merchants should promptly seek the expertise of cybersecurity professionals, implement patches, and reassess security protocols to avert further damage.
